Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release 3.3.1 (Portable) detected as Trojan by Windows Defender #434

Open
perroboc opened this issue Jan 12, 2022 · 4 comments
Open

Release 3.3.1 (Portable) detected as Trojan by Windows Defender #434

perroboc opened this issue Jan 12, 2022 · 4 comments

Comments

@perroboc
Copy link

In windows 10, I'm unable to download the portable version of release 3.3.1, because Windows Defender detects Trojan:Win32/Tisifi.RR!MTB in the binary file:

webfile: C:\Users\Álvaro\Downloads\todotxt-portable-3.3.1.zip|https://objects.githubusercontent.com/github-production-release-asset-2e65be/1613966/70d3f000-c899-11e9-8986-04513476f0f5?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20220112%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20220112T220304Z&X-Amz-Expires=300&X-Amz-Signature=de9c6c0406325908e8accf9506ab8c8218727a77ece0a06d02705cd9773f41be&X-Amz-SignedHeaders=host&actor_id=2722773&key_id=0&repo_id=1613966&response-content-disposition=attachment%3B%20filename%3Dtodotxt-portable-3.3.1.zip&response-content-type=application%2Foctet-stream|pid:15376,ProcessStart:132864985856192890

VirusTotal doesn't detect anything, nor does OPSwat

@perroboc perroboc changed the title release Release 3.3.1 (Portable) detected as Trojan by Windows Defender Jan 12, 2022
@CodeGrammer45
Copy link

Update 2022-04-12:

I got reached out to by the cyber team at my work about a malicious file on my computer. Decided to check the .exe for the latest release of todotxt.net, and both VirusTotal and OPSwat found potential malware.

@Largo
Copy link

Largo commented Jun 29, 2022

Update: 2022-06-29: Windows Defender is not finding anything and only 2 minor anti-virus vendors detect the file, so it's safe to say that it is a false positive.

@Boggin
Copy link

Boggin commented Jul 1, 2022

Update: 2022-06-29: Windows Defender is not finding anything and only 2 minor anti-virus vendors detect the file, so it's safe to say that it is a false positive.

Trojan:Win32/Tisifi.RR!MTB
Windows Defender is flagging the release. @Largo, it was specifically mentioned it OP's report.

@Largo
Copy link

Largo commented Jul 1, 2022

Strange. I confirmed with the hash that I downloaded the same release as OP and checked it locally with windows defender and re-uploaded it to Virus Total. I'm using definitions 1.369.576.0 from 2022-07-01

Maybe try submitting it to
Submit a file for malware analysis - Microsoft Security Intelligence

Another project is facing a similiar issue: gus33000/UUPMediaCreator#18

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants